PT-2026-20918 · Unknown · Open-Webui

·

CVE-2026-26193

·

Published

2026-02-19

·

Updated

2026-07-13

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open WebUI versions prior to 0.6.44
Description Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Manually modifying chat history allows setting the embeds property on a response message. The content of this property is loaded into an iFrame with a sandbox that has allow-scripts and allow-same-origin set, bypassing the "iframe Sandbox Allow Same Origin" configuration. This enables stored cross-site scripting (XSS) on the affected chat, and the resulting malicious link can be shared with other users on the instance. The issue occurs when the chat is in the shared format.
Recommendations Update to version 0.6.44 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26193
GHSA-VJM7-M4XH-7WRC
PYSEC-2026-2760

Affected Products

Open-Webui